CVE-2022-21686
Summary
| CVE | CVE-2022-21686 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-26 20:15:00 UTC |
| Updated | 2022-02-04 16:21:00 UTC |
| Description | PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Prestashop | Prestashop | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Server Side Twig Template Injection · Advisory · PrestaShop/PrestaShop · GitHub | CONFIRM | github.com | |
| Release PrestaShop 1.7.8.3 · PrestaShop/PrestaShop · GitHub | MISC | github.com | |
| Merge pull request from GHSA-mrq4-7ch7-2465 · PrestaShop/PrestaShop@d02b469 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.